At the most basic level, pick up any device supported by DD-WRT from a local store ($50-$100) - or ebay for even less. I've also worked with some of the smaller Sonicwall devices - and they are OK, but the nicer features are definitely held back for the more expensive models.
If there's enough money I'd go with an ASA5505. Otherwise I'd use a soekris box running OpenBSD or another *nix of your choice. Lastly, if even the soekris box was too much I'd go with an old PC and again run one of the *nixs on it.
I'm aware that an old PC is larger, generates more heat, and consumes more power then a SOHO router\firewall but I've never been impressed with the reliability of the wrt54 and the like. Sure, running alternate firmware on it helps a lot but it's still not something I'd care to use.
Any of the linux distros on a pc would give you great control, if you're willing to deal with downtime when the hard drive, fan or memory fail... what specific requirements do you have? I haven't had experience with, but would like to try out the vyatta devices.. I think they start at about $800.
1. 10-20 Windows based users.
2. Workgroup, no AD.
3. Web browsing, proxy, Blacklisting available.
4. Easy interface for novice to intermediate administration.
5. Inexpensive to purchase and maintain.
Yes, I agree that most Linux distro's have most of these features. The most prominent issue would be that the administrator would be familiar with Windows (Point and Click interface).
> the administrator would be familiar with Windows (Point and Click interface)
That's not a feature of Windows only (e.g. Firestarter http://www.fs-security.com/). But maybe you'd rather not use your old Pentium 3 for the job anyway.
pfsense sounds like it may be a fit for what you are looking for (http://www.pfsense.org). It's BSD and light weight. It provides traffic graphs, dhcp, vpn server and much more with just a webpage to administer it. I've used it in small offices as well as at home.
Permalink Reply by Yuri on September 11, 2009 at 2:47pm
I would recommend Untangle. It might be a little more expensive as it needs a basic PC to run rather than a router (eg: DD-WRT) but you get so much more, not the least of which is a very good Spam Blocker.